Chinese Hackers Impersonate US AI Experts in Phishing Campaign
A new report says Chinese hackers are impersonating American AI professionals to steal emails from other artificial intelligence (AI) experts. That report, issued Thursday (Oct. 1) by cybersecurity firm Proofpoint, said that a hacking group known as “TA419” has since last year routinely attempted to steal passwords from think tanks, defense contractors, universities and law […] The post Chinese…
A report by cybersecurity firm Proofpoint revealed that Chinese hackers are impersonating American AI experts to steal emails from other AI professionals. The hacking group, known as "TA419," has been attempting to steal passwords from think tanks, defense contractors, universities, and law firms in Japan and the United States since last year.
Proofpoint predicts that TA419 will likely continue targeting policy experts working on technologies of interest to the Chinese government. The company advises organizations in TA419's scope to adopt phishing-resistant, origin-bound authentication methods, such as passkeys, and treat unsolicited subject-matter outreach as a potential pretext stage.
In a recent campaign starting in July, TA419 impersonated former White House Office of Science and Technology Policy principal deputy director Lynne Parker and economist/foreign policy expert Heidi Crebo-Rediker. The emails promised AI-themed collaborations or initiatives, leading to a credential phishing page designed to gain access to the target's cloud account.
The hackers targeted AI policy experts at American think tanks, law firms, and universities. One victim, former White House official Alex Engler, recognized the impersonation and reported it to others in the field. The Federal Trade Commission notes that impersonation scams, in which criminals pose as trusted authorities or familiar contacts, are among the most common types of fraud reported by consumers, costing Americans nearly $3 billion in 2024.
Written by urgent.news from PYMNTS's reporting — not their text. Machine-written — may contain errors; check the original before relying on it.